CVE-2011-0059

high

Description

Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.

References

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14473

https://bugzilla.mozilla.org/show_bug.cgi?id=573873

http://www.securityfocus.com/bid/46652

http://www.redhat.com/support/errata/RHSA-2011-0313.html

http://www.mozilla.org/security/announce/2011/mfsa2011-10.html

http://www.mandriva.com/security/advisories?name=MDVSA-2011:041

http://support.avaya.com/css/P8/documents/100128655

http://downloads.avaya.com/css/P8/documents/100133195

Details

Source: Mitre, NVD

Published: 2011-03-02

Updated: 2017-09-19

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High